Top stories.
- Australian police arrest two suspected TeamPCP members.
- CISA says more than 100 water and wastewater systems were targeted in cyberattacks in July.
- UK airports disclose breach.
Australian police arrest two suspected TeamPCP members.
The Australian Federal Police (AFP) have arrested two alleged members of the TeamPCP cybercriminal group, KrebsOnSecurity reports. The two men, aged 21 and 23, were arrested in Western Australia with assistance from the Western Australia Police Force (WAPF) and intelligence from the US Federal Bureau of Investigation (FBI).
TeamPCP is a financially motivated threat actor known for conducting software supply chain attacks against popular developer tools such as TanStack, Trivy, and LiteLLM. The AFP said in a press release, "It is estimated the malicious code potentially compromised more than 1000 organisations globally, enabling the theft of more than 500,000 credentials, and the exfiltration of at least 300 gigabytes of data. The alleged compromise of a small number of trusted software components had a significant global impact. To date, the financial impact includes global remediation costs estimated to be hundreds of millions of dollars."
CISA says more than 100 water and wastewater systems were targeted in cyberattacks in July.
The US Cybersecurity and Infrastructure Security Agency (CISA) says attackers hit more than 100 internet-exposed water and wastewater systems last month, SecurityWeek reports. These attacks primarily targeted programmable logic controllers (PLCs) that were connected directly to cellular modems. The agency urges "all critical infrastructure organizations to route all necessary remote access through a secure gateway, firewall, VPN, or other centrally managed access solution, rather than connecting directly to a PLC, human-machine interface (HMI), or remote terminal unit (RTU)."
POLITICO reports that the Trump administration plans to announce a program to provide free cybersecurity services to US water facilities, led by the Office of the National Cyber Director. A source told the publication that the program will begin as a "proof of concept" in Texas before expanding to other states. The initiative would enlist private cybersecurity companies to provide the services.
UK airports disclose data breach.
Manchester Airports Group (MAG), which operates the Manchester, London Stansted, and East Midlands airports in the UK, said a cyberattack exposed data belonging to approximately 8.7 million customers, the Guardian reports. MAG said the incident involved "car park, lounge and fast-track bookings, and in-airport wifi sign-ups." The company added that "at no point has passenger safety or aviation security been compromised."
MAG warns customers to be on the lookout for phishing attacks using their personal information.